diff --git a/.github/workflows/merge-schedule.yml b/.github/workflows/merge-schedule.yml index c300d822..1ebb4148 100644 --- a/.github/workflows/merge-schedule.yml +++ b/.github/workflows/merge-schedule.yml @@ -18,7 +18,7 @@ jobs: with: egress-policy: audit - - uses: gr2m/merge-schedule-action@b00191bec092ae480b63bf466fb94b5474b71cdd # v2.4.3 + - uses: gr2m/merge-schedule-action@678b3399de95e30d1c7c48b319b3b86b533d2ab9 # v2.4.4 with: # Merge method to use. Possible values are merge, squash or # rebase. Default is merge. diff --git a/.github/workflows/scorecards.yml b/.github/workflows/scorecards.yml index 46029473..ed783807 100644 --- a/.github/workflows/scorecards.yml +++ b/.github/workflows/scorecards.yml @@ -63,7 +63,7 @@ jobs: # Upload the results as artifacts (optional). Commenting out will disable uploads of run results in SARIF # format to the repository Actions tab. - name: "Upload artifact" - uses: actions/upload-artifact@604373da6381bf24206979c74d06a550515601b9 # v4.4.1 + uses: actions/upload-artifact@b4b15b8c7c6ac21ea08fcf65892d2ee8f75cf882 # v4.4.3 with: name: SARIF file path: results.sarif @@ -71,6 +71,6 @@ jobs: # Upload the results to GitHub's code scanning dashboard. - name: "Upload to code-scanning" - uses: github/codeql-action/upload-sarif@c36620d31ac7c881962c3d9dd939c40ec9434f2b # v3.26.12 + uses: github/codeql-action/upload-sarif@f779452ac5af1c261dce0346a8f964149f49322b # v3.26.13 with: sarif_file: results.sarif